
For more troubleshooting information, see
https://cisco.com/go/fmc-reg-error
Configure a Basic Security Policy
This section describes how to configure a basic security policy with the following settings:
• Inside and outside interfaces—Assign a static IP address to the inside interface, and use DHCP for the
outside interface.
• DHCP server—Use a DHCP server on the inside interface for clients.
• Default route—Add a default route through the outside interface.
• NAT—Use interface PAT on the outside interface.
• Access control—Allow traffic from inside to outside.
To configure a basic security policy, complete the following tasks.
Configure Interfaces, on page 27
Configure the DHCP Server, on page 30
Add the Default Route, on page 31
.
Allow Traffic from Inside to Outside, on page 35
.
Deploy the Configuration, on page 36
.
Configure Interfaces
Enable the threat defense interfaces, assign them to security zones, and set the IP addresses. Typically, you
must configure at least a minimum of two interfaces to have a system that passes meaningful traffic. Normally,
you would have an outside interface that faces the upstream router or internet, and one or more inside interfaces
for your organization’s networks. Some of these interfaces might be “demilitarized zones” (DMZs), where
you place publically-accessible assets such as your web server.
A typical edge-routing situation is to obtain the outside interface address through DHCP from your ISP, while
you define static addresses on the inside interfaces.
The following example configures a routed mode inside interface with a static address and a routed mode
outside interface using DHCP.
Cisco Firepower 1100 Getting Started Guide
27
Threat Defense Deployment with the Management Center
Configure a Basic Security Policy
Содержание Firepower 1100
Страница 2: ......
Страница 110: ...Cisco Firepower 1100 Getting Started Guide 108 Threat Defense Deployment with the Device Manager What s Next ...
Страница 177: ... 2022 Cisco Systems Inc All rights reserved ...
Страница 178: ......